Capital, AI Agents, and Governance: India’s Tech Inflection Point
AI Can Act. But Who Holds the Brakes?
We celebrate AI for what it can do. The harder engineering question is what it should be allowed to do-and how to stop it.
In 2015, a pricing error on an Indian e-commerce platform turned a Rs185 product into an Rs82,740 listing. Ninety customers ordered before the business rolled it back; nothing shipped. The enduring lesson: a system capable of consequential action must also be capable of stopping safely.
Capital grows. Control systems must catch up.
Reported Indian tech funding reached $10.3 billion in the first nine months of 2026, up 6.2% year on year, even as funding rounds, first-time-funded companies and soonicorn additions declined. Alongside this, AI is moving from advice to action, while international leaders are pressing for stronger safeguards. Capital is concentrating; technology is gaining agency.
My concern is not whether agents can act. It is whether our architectures can govern those actions at machine speed.
An assistant may only read data. An agent can create records, initiate transactions or deploy resources. Authentication establishes identity; authorisation must define what actions are permitted, under which conditions, and within which limits.
Design for bounded autonomy
Enterprise agents need scoped identities, least-privilege access, constrained tools, transaction limits, approval for irreversible actions and end-to-end audit trails. “Human in the loop” is not a safeguard if the human lacks context, time or authority to intervene.
The key question is shifting from “What can this model generate?” to “Which actions can it safely complete-and how do we reverse them?” A demonstration without policy enforcement or a reliable kill switch is a prototype, not a production system.
Security must be designed in, not appended
The report of an AI agent accessing non-sensitive healthcare data through an Australian government portal exposes a familiar weakness: when models can use systems, ordinary permissions can become routes to unintended consequences.
For sensitive personal and public-sector data, sovereignty matters. But data residency alone is not safety. Security, purpose limitation, auditability and accountable data lifecycles must be built into workflows from the start.
Founders should fund evaluations, monitoring, incident response and rollback alongside the product. Production AI must account for adversarial inputs, unreliable data and partial failures-not treat them as temporary edge cases.
More capital is not the same as a stronger ecosystem
The funding pattern may reflect greater investor conviction, but concentration is not automatically resilience. Larger cheques can accelerate infrastructure and talent; they cannot manufacture the next generation of founders. A healthy ecosystem needs both deep capital and room for diverse early-stage ideas.
For young founders, the lesson is direct: build security and accountability in before growth, not after it.
Four questions I would ask of every AI roadmap
- Can each agent prove which identity authorised an action?
- Does it have only the access it needs, with permissions that expire?
- Can high-impact actions be reviewed, reversed or stopped before harm escalates?
- Are reliability, fairness and security tested continuously-not just before launch?
Architecture is how good intentions become enforceable behaviour. The future will belong not to systems that act most, but to organisations that can prove why they acted, what they changed and how they put it right.
About the Author: Sanjeev Sarma is the Founder Director and Chief Software Architect at Webx Technologies. With a core focus on Generative AI integration, Cloud-Native Scalability, and Enterprise Software Architecture, he has spent over two decades driving digital transformation across Northeast India and beyond. Beyond his corporate leadership, Sanjeev is deeply invested in shaping the future of the IT industry. He serves as an Industry Expert on the Board of Studies for Assam Don Bosco University’s School of Technology, advises state technology committees, and actively mentors emerging tech startups at STPI. He brings a unique, dual perspective of high-level enterprise execution and future-ready academic curriculum development.